PT-2020-10286 · Ixp · Ixp Easyinstall

Published

2020-01-23

·

Updated

2020-01-29

·

CVE-2019-19893

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions IXP EasyInstall version 6.2.13723
Description The issue allows an unauthenticated attacker to perform Directory Traversal on the Engine Service via TCP port 8000. This enables access to the server's filesystem with the access rights of NT AUTHORITYSYSTEM.
Recommendations For IXP EasyInstall version 6.2.13723, consider restricting access to the Engine Service on TCP port 8000 until a patch is available. As a temporary workaround, limit the access rights of the NT AUTHORITYSYSTEM to minimize potential damage. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-19893

Affected Products

Ixp Easyinstall